PkgRadar

PyPI · pypi.org

obra

Python Bun Js Exec: Python file references the Bun JavaScript runtime — cross-language execution

Why PkgRadar flagged 3.7.54

SeveritySignalEvidence
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · obra/config/explorer/descriptions.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · obra/hybrid/install_target.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · obra/hybrid/tooling_discovery.py
highPython Bun Js ExecPython file references the Bun JavaScript runtime — cross-language execution · obra/hybrid/story0/verification_installer.py

Scanned versions

VersionVerdictScoreScanned (UTC)
3.7.54High risk732026-06-16
3.7.53High risk682026-06-14
3.7.52High risk682026-06-13
3.7.51High risk682026-06-13
3.7.50High risk682026-06-13
3.7.49High risk682026-06-12
3.7.48High risk682026-06-12
3.7.47High risk682026-06-12
3.7.46High risk682026-06-11
3.7.44High risk682026-06-11
3.7.43High risk682026-06-10
3.7.42Review182026-06-04
3.7.41Review182026-06-02
3.7.40Review182026-05-30
3.7.39Review182026-05-30

Campaign attribution

Part of the Shai-Hulud (PyPI) campaign.

Block this in CI

PkgRadar gates obra (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem pypi obra==3.7.54